06-08-2023 05:09 AM
I have a bunch of S2S VPN's terminating to an edge ASA firewall.
I'd like to add a new ASA/FTD appliance inside our network for the VPN's to terminate to. We have dual WAN circuits so if a specific circuit drops currently we lose the VPN connections until it is restored, moving the peer device inside means the traffic should reroute automatically via the alternate WAN circuit.
Is it possible to redirect currently configured VPN traffic to another address (DNAT?) to save having to contact each supplier to reconfigure their peer address.
06-08-2023 05:16 AM
06-08-2023 05:35 AM
thanks, but that requires the other end to reconfigure with a failover address. I'm hoping to avoid, or at least delay the requirement to contact a lot of customers to reconfigure their VPN.
06-08-2023 06:15 AM
sorry I think there is no other way
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide